
scan2payme Security & Risk Analysis
wordpress.org/plugins/scan2paymePlugin for displaying payment QR-Codes in WooCommerce order pages.
Is scan2payme Safe to Use in 2026?
Generally Safe
Score 92/100scan2payme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scan2payme" plugin, in version 1.0.4, exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent coding practices in several areas. All SQL queries are properly prepared, and all output is correctly escaped, indicating a strong defense against common injection and XSS vulnerabilities. There are no file operations or external HTTP requests, further reducing the attack surface. The absence of bundled libraries is also a good sign, as it avoids potential vulnerabilities from outdated dependencies.
However, a significant concern arises from the attack surface analysis. The plugin has a single entry point through an AJAX handler that completely lacks authentication checks. This presents a critical risk, as any unauthenticated user could potentially interact with this handler, leading to unintended actions or information disclosure. While taint analysis did not reveal any issues, the presence of an unprotected AJAX endpoint bypasses the need for taint to manifest a vulnerability, as the lack of authorization is the primary flaw.
Furthermore, the plugin's vulnerability history is entirely clean, with no recorded CVEs. While this is a positive indicator, it's important to note that a clean history does not guarantee future security. Coupled with the unprotected AJAX endpoint, this suggests that while the developers may have good intentions, there's a critical oversight in securing critical functionalities. The plugin's strengths in preventing common web vulnerabilities are overshadowed by the single, yet significant, vulnerability in its authentication mechanism.
Key Concerns
- AJAX handler without authentication
scan2payme Security Vulnerabilities
scan2payme Release Timeline
scan2payme Code Analysis
Output Escaping
scan2payme Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
scan2payme Maintenance & Trust
Maintenance Signals
Community Trust
scan2payme Alternatives
Checkout Gateway for IRIS
checkout-gateway-iris
Unofficial IRIS checkout payment gateway for WooCommerce. Accept payments via IRIS and manage order statuses efficiently.
Czech QR Payments for WooCommerce
czech-qr-code-bank-transfer-payment-for-woocommerce
Payment method for fast QR code bank transfer payment from Czech banking mobile apps
BigVNN Payment Gateway for VietQR
bigvnn-vietqr-payment-gateway
VietQR WooCommerce is a powerful payment gateway that allows your customers to pay quickly by scanning a dynamically generated VietQR code.
Bytenet Static QR Payments with IRIS for WooCommerce
payment-gateway-iris-for-woocommerce
Adds IRIS as a payment method in WooCommerce using a static QR code.
UPI QR Code Payment Gateway for WooCommerce
upi-qr-code-payment-for-woocommerce
This Plugin enables WooCommerce shop owners to get direct and instant payments through UPI apps like BHIM, GooglePay, PhonePe or any banking UPI app.
scan2payme Developer Profile
1 plugin · 0 total installs
How We Detect scan2payme
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scan2payme/js/scan2payme-admin.jsscan2payme/js/scan2payme-admin.js?ver=HTML / DOM Fingerprints
<!-- TODO does the default value work if this is a fresh installation? -->data-nonce="scan2payme-account-nonce"scan2payme_ajax_object/wp-json/scan2payme/v1/options